Executive brief
Intel's NPU (Neural Processing Unit) Driver is used to enable AI acceleration on systems with Intel processors. An authenticated local user can trigger an out-of-bounds memory read that crashes the system or degrades performance, resulting in denial of service. This affects both Linux and Windows versions of the driver.
Technical details
This vulnerability is an out-of-bounds read in the Intel NPU Driver affecting Ring 3 user applications. An authenticated local attacker with low complexity can trigger this memory access violation without special knowledge or user interaction, potentially via improper buffer management or bounds checking. The attack vector is local, requiring prior authentication but not elevated privileges. The vulnerability impacts system availability (high severity) and has a minor integrity impact. A patch is available for both Linux (version 1.32.0 or later) and Windows (version 32.0.100.4723 or later).
Affected products
- Intel NPU Driver for Linux before 1.32.0
- Intel NPU Driver for Windows before 32.0.100.4723
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Patches available: Linux 1.32.0 and Windows 32.0.100.4723